FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0095

This CVE name corresponds to:

Entered Topic
2005-01-12 squid -- denial of service with forged WCCP messages

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0095
Phase Assigned(20050118)

Description

The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.

References

Source Reference
CONFIRM http://www.squid-cache.org/Advisories/SQUID-2005_2.txt
CONFIRM http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch
CONECTIVA CLA-2005:923
DEBIAN DSA-651
FEDORA FLSA-2006:152809
GENTOO GLSA-200501-25
MANDRAKE MDKSA-2005:014
REDHAT RHSA-2005:060
REDHAT RHSA-2005:061
SUSE SUSE-SA:2005:006
TRUSTIX 2005-0003
BID 12275
OSVDB 12886
OVAL oval:org.mitre.oval:def:10269
SECTRACK 1012882
SECUNIA 13825